Live opening · Posted 8 hours ago

Internal Auditor

OnHires · Europe | Poland | Remote - Slovakia | Remote — Romania | Lithuania | Latvia | Ukraine | Estonia | Limassol | Slovenia
Ashby Yes FullTime
You are 8 hours behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 8 hours ago
CompanyOnHires
LocationEurope | Poland | Remote - Slovakia | Remote — Romania | Lithuania | Latvia | Ukraine | Estonia | Limassol | Slovenia
Job typeFullTime
Work modeYes
SourceAshby
Listed8 hours ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
3 min from Ashby publishing this role to us finding it
12 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
71,480 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

Remote | EU/EEA | Regulated Crypto & Payments Company | Part-time B2B Consultancy
About the Client
Our client is a global fintech company operating at the intersection of crypto and traditional payments. It serves millions of users worldwide through two business lines: a B2C retail platform for buying, selling, and swapping crypto, and B2B infrastructure providing on/off-ramp APIs, payouts, and compliance infrastructure for fintechs, wallets, and platforms.
The company's EU operating entity holds a MiCA CASP authorisation and a Payment Institution licence under PSD2, serving EU customers and powering a regulated B2B platform that fintechs, neobanks, PSPs, and Web3 companies build on - under the company's licences. Its control environment is part of the product, not back-office overhead.
About the Role
The company is looking for an Internal Auditor to run the third line of defence for its EU-licensed entity.
This is not a compliance role and not a monitoring role with an audit title. You audit Compliance controls - you do not execute them. You report functionally to the Management Board, you set your own severity ratings, and you deliver findings to the people who run the company, including when the finding is about them.
The function already exists. The Charter, Audit Universe, Internal Audit Plan and findings register are in place and Board-approved. This is not a rebuild of the methodology - it is delivering the plan with rigour, keeping the register alive and closed out with evidence, and putting the Board and the supervisor in a position where the control environment can be answered from the file.
- What You'll Do
Own and maintain the risk-based Internal Audit Plan across MiCA CASP and PSD2 PI obligations, AML/KYC/CTF controls, ICT and security (DORA), custody and segregation of client assets, safeguarding of client funds, outsourcing and third-party risk, governance and financial controls.
- Execute engagements end-to-end - design the programme, select samples, test controls, rate severity and regulatory impact.
- Write Board-ready audit reports with findings that hold up under challenge and recommendations someone can actually act on.
- Obtain remediation plans with named owners and deadlines; track and verify closure against evidence, not assertion.
- Present findings and remediation status to the Management Board - quarterly updates and the annual Internal Audit Report.
- Deliver the annual independent AML/CFT audit and the DORA ICT framework audit and follow-up.
- Scope, direct, and challenge external specialists where an engagement needs deep technical testing.
- Maintain the audit evidence that supports regulatory supervisory reviews and inspections.
What We're Looking For
Required
- 5+ years of internal audit or internal control experience in a regulated financial services entity - bank, payment institution, EMI, investment firm, insurer, regulated fintech or crypto/VASP. Unregulated-only experience will not be considered.
- Hands-on audit experience with at least one fintech, payment institution, EMI, crypto exchange or VASP - execution, not advisory theory.
- Working knowledge of at least two of MiCA, PSD2, AMLD5/6 and DORA, with the ability to turn a regulatory obligation into a test programme.
- Strong understanding of AML/KYC/CTF frameworks and how to audit their effectiveness.
- Evidence of independence in practice - critical findings delivered to senior management or a Board and held under challenge.
- Ability to run an engagement unsupervised and to make and defend a professional judgement on control severity.
- Sufficient ICT and information security audit literacy to scope a DORA engagement and to direct and challenge an external technical specialist.
- Fluent professional English - reports go to the Board and to the regulator as written.
- Hands-on use of AI tools in audit work - planning, analysis, testing or reporting - with concrete examples.
- Right to work and tax residence in the EU/EEA, with eligibility to be appointed to an internal control function of a licensed entity.
Nice to Have
- MiCA CASP post-authorisation audit experience.
- PSD2 / EMI safeguarding, own funds and scheme-compliance audit experience.
- Deep ICT / information security audit capability, including DLT infrastructure, wallet security and key management.
- DORA operational resilience, outsourcing and third-party risk audit experience.
- Custody and segregation-of-client-assets audit experience.
- Travel rule (FATF / EU TFR) audit experience.
- Experience with a Baltic or other EU financial supervisor.
- Board- or regulator-facing communication experience.
- CIA, CISA, ACCA or an EU-recognised internal audit qualification.
- Russian or Latvian.
What Makes This Role Different
- This role is for auditors who want real independence, not a compliance review with an audit title.
- You inherit a working function - Charter, plan, universe, and findings register already exist and are Board-approved - and you run it, not rebuild it from scratch.
- You report functionally to the Board, set your own severity ratings, and deliver findings directly to the people who can act on them, including senior leadership.
- You'll work across one of the more complex dual-licensed perimeters in Europe (MiCA CASP + PSD2 PI), with direct Board access and budget for external technical specialists where needed.
Working Environment
- Remote across the EU/EEA, with periodic in-person days at the company's EU office (roughly quarterly, or around Board meetings).
- Part-time engagement (~0.5 FTE), B2B consultancy contract.
- Functional reporting to the Management Board; no team, no review layer - full ownership of the function.
- Scheduled checkpoints at scope memo, draft report and Board reporting stages; no involvement from management in fieldwork, findings or ratings.

Employment type
FullTime

Work arrangement
Yes

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App